PT-2022-15370 · Ibm · Ibm Sterling Partner Engagement Manager

Published

2022-04-01

·

Updated

2023-08-08

·

CVE-2022-22331

CVSS v3.1

7.1

High

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:H/I:L/A:N
Name of the Vulnerable Software and Affected Versions IBM Sterling Partner Engagement Manager version 6.2.0
Description The issue allows a remote authenticated attacker to obtain sensitive information or modify user details due to an insecure direct object vulnerability (IDOR).
Recommendations For IBM Sterling Partner Engagement Manager version 6.2.0, consider restricting access to sensitive information and user details until a patch is available. As a temporary workaround, limit the modification of user details to authorized personnel only.

Fix

IDOR

Weakness Enumeration

Related Identifiers

CVE-2022-22331

Affected Products

Ibm Sterling Partner Engagement Manager